WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 6,351–6,400 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 128 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Rapid Car Check Vehicle Data Plugin free-vehicle-data-uk Broken Access Control No login needed ≤ 2.0 CVE-2026-39687 Patchstack
5.3 Medium BSK PDF Manager Plugin bsk-pdf-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 3.7.2 CVE-2026-39686 Patchstack
5.3 Medium The Moneytizer Plugin the-moneytizer Broken Access Control No login needed ≤ 10.0.10 CVE-2026-39685 Patchstack
7.5 High OrganicFood Theme organicfood Local File Inclusion ≤ 3.6.4 CVE-2026-39684 Patchstack
5.9 Medium Garden Gnome Package Plugin garden-gnome-package Cross-Site Scripting ≤ 2.4.1 CVE-2026-39683 Patchstack
5.3 Medium linkPizza-Manager Plugin linkpizza-manager Broken Access Control No login needed ≤ 5.5.5 CVE-2026-39682 Patchstack
7.5 High Homeo Theme homeo Local File Inclusion ≤ 1.2.59 CVE-2026-39681 Patchstack
5.3 Medium Diet Calorie Calculator Plugin diet-calorie-calculator Broken Access Control No login needed ≤ 1.1.1 CVE-2026-39680 Patchstack
7.5 High Freeio Theme freeio Local File Inclusion ≤ 1.3.21 CVE-2026-39679 Patchstack
5.3 Medium Pinpoint Booking System Plugin booking-system Broken Access Control No login needed ≤ 2.9.9.6.5 CVE-2026-39678 Patchstack
7.5 High Emphires Theme emphires Local File Inclusion ≤ 3.9 CVE-2026-39677 Patchstack
5.3 Medium Download Manager Plugin download-manager Broken Access Control No login needed ≤ 3.3.52 Fixed in 3.3.53 CVE-2026-39676 Patchstack
5.3 Medium Court Reservation Plugin court-reservation Broken Access Control No login needed ≤ 1.10.11 CVE-2026-39675 Patchstack
6.5 Medium MK Google Directions Plugin google-distance-calculator Cross-Site Scripting ≤ 3.1.1 CVE-2026-39674 Patchstack
5.3 Medium iZooto Plugin izooto-web-push Broken Access Control No login needed ≤ 3.7.20 CVE-2026-39673 Patchstack
5.3 Medium ShipTime: Discounted Shipping Rates Plugin shiptime-discount-shipping Broken Access Control No login needed ≤ 1.1.1 CVE-2026-39672 Patchstack
7.1 High Extra Fees Plugin for WooCommerce Plugin woo-conditional-product-fees-for-checkout Cross-Site Request Forgery No login needed ≤ 4.3.3 CVE-2026-39671 Patchstack
6.0 Medium Visual Link Preview Plugin visual-link-preview Server-Side Request Forgery ≤ 2.3.0 CVE-2026-39670 Patchstack
5.3 Medium NitroPack Plugin nitropack Broken Access Control No login needed ≤ 1.19.3 Fixed in 1.19.4 CVE-2026-39669 Patchstack
5.3 Medium Book Previewer for Woocommerce Plugin book-previewer-for-woocommerce Broken Access Control No login needed ≤ 1.0.6 CVE-2026-39668 Patchstack
5.9 Medium Korea SNS Plugin korea-sns Cross-Site Scripting ≤ 1.7.0 CVE-2026-39667 Patchstack
6.5 Medium Hello Bar Popup Builder Plugin hellobar Cross-Site Scripting ≤ 1.5.1 CVE-2026-39666 Patchstack
6.5 Medium SEO Friendly Images Plugin seo-image Cross-Site Scripting ≤ 3.0.5 CVE-2026-39665 Patchstack
5.3 Medium Leadrebel Plugin leadrebel Broken Access Control No login needed ≤ 1.0.2 CVE-2026-39664 Patchstack
5.3 Medium TrueBooker Plugin truebooker-appointment-booking Broken Access Control No login needed ≤ 1.1.5 CVE-2026-39663 Patchstack
5.3 Medium Product Price by Formula for WooCommerce Plugin product-price-by-formula-for-woocommerce Broken Access Control No login needed ≤ 2.5.6 CVE-2026-39662 Patchstack
5.3 Medium Panda Pods Repeater Field Plugin panda-pods-repeater-field Broken Access Control No login needed ≤ 1.5.12 CVE-2026-39658 Patchstack
5.3 Medium leadlovers forms Plugin leadlovers-forms Broken Access Control No login needed ≤ 1.0.2 CVE-2026-39657 Patchstack
5.3 Medium Razorpay for WooCommerce Plugin woo-razorpay Broken Access Control No login needed ≤ 4.8.2 CVE-2026-39656 Patchstack
5.9 Medium WP Simple HTML Sitemap Plugin wp-simple-html-sitemap Cross-Site Scripting ≤ 3.8 CVE-2026-39654 Patchstack
4.3 Medium Video Conferencing with Zoom Plugin video-conferencing-with-zoom-api Broken Access Control ≤ 4.6.6 CVE-2026-39653 Patchstack
5.3 Medium iGMS Direct Booking Plugin igms-direct-booking Broken Access Control No login needed ≤ 1.3 CVE-2026-39652 Patchstack
6.5 Medium Total Poll Lite Plugin totalpoll-lite Broken Access Control ≤ 4.12.0 CVE-2026-39651 Patchstack
5.3 Medium UnitechPay Plugin unitechpay-paiements-mobile-money Broken Access Control No login needed ≤ 1.0.2 CVE-2026-39650 Patchstack
5.3 Medium Royale News Plugin royale-news Broken Access Control No login needed ≤ 2.2.4 CVE-2026-39649 Patchstack
5.3 Medium Cream Blog Plugin cream-blog Broken Access Control No login needed ≤ 2.1.7 CVE-2026-39648 Patchstack
5.4 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Server-Side Request Forgery No login needed ≤ 5.11 CVE-2026-39647 Patchstack
6.5 Medium Leaflet Map Plugin leaflet-map Cross-Site Scripting ≤ 3.4.4 CVE-2026-39646 Patchstack
5.4 Medium GlobalPayments WooCommerce Plugin global-payments-woocommerce Server-Side Request Forgery No login needed ≤ 1.18.0 CVE-2026-39645 Patchstack
5.3 Medium Wp Ultimate Review Plugin wp-ultimate-review Broken Access Control No login needed ≤ 2.3.8 CVE-2026-39644 Patchstack
5.3 Medium Payment Plugins for PayPal WooCommerce Plugin pymntpl-paypal-woocommerce Broken Access Control No login needed ≤ 2.0.13 CVE-2026-39643 Patchstack
6.5 Medium Blackfyre Theme blackfyre Cross-Site Request Forgery No login needed ≤ 2.5.4 CVE-2026-39641 Patchstack
9.6 Critical Theme Editor Plugin theme-editor Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Remote Code Execution No login needed ≤ 3.2 CVE-2026-39640 Patchstack
6.5 Medium RPS Include Content Plugin rps-include-content Broken Access Control ≤ 1.2.2 CVE-2026-39639 Patchstack
5.9 Medium Qubely Plugin qubely Cross-Site Scripting ≤ 1.8.14 CVE-2026-39638 Patchstack
5.3 Medium Mogi Theme mogi Arbitrary Shortcode Execution No login needed ≤ 1.2.3 CVE-2026-39637 Patchstack
6.5 Medium Livemesh Addons for Elementor Plugin addons-for-elementor Cross-Site Scripting ≤ 9.0 CVE-2026-39636 Patchstack
5.4 Medium Grand Magazine Theme grandmagazine Cross-Site Request Forgery No login needed ≤ 3.5.5 CVE-2026-39635 Patchstack
5.4 Medium Grand Portfolio Theme grandportfolio Cross-Site Request Forgery No login needed ≤ 3.3 CVE-2026-39634 Patchstack
6.5 Medium Grand Car Rental Plugin grandcarrental Cross-Site Request Forgery No login needed ≤ 3.6.9 CVE-2026-39633 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only